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Question: 1 


A security team is discussing lessons learned and suggesting process changes after a security breach 
incident. During the incident, members of the security team failed to report the abnormal system 
activity due to a high project workload. Additionally, when the incident was identified, the response 
took six hours due to management being unavailable to provide the approvals needed. Which two 
steps will prevent these issues from occurring in the future? (Choose two.) 


A. Introduce a priority rating for incident response workloads. 
B. Provide phishing awareness training for the fill security team. 
C. Conduct a risk audit of the incident response workflow. 

D. Create an executive team delegation plan. 


E. Automate security alert timeframes with escalation triggers. 


Answer: AE 


Question: 2 


An engineer is investigating a ticket from the accounting department in which a user discovered an 
unexpected application on their workstation. Several alerts are seen from the intrusion detection 
system of unknown outgoing internet traffic from this workstation. The engineer also notices a 
degraded processing capability, which complicates the analysis process. Which two actions should 
the engineer take? (Choose two.) 


A. Restore to a system recovery point. 
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B. Replace the faulty CPU. 
C. Disconnect from the network. 
D. Format the workstation drives. 


E. Take an image of the workstation. 


Answer: AE 


Question: 3 


Refer to the exhibit. 


What should an engineer determine from this Wireshark capture of suspicious network traffic? 


A. There are signs of SYN flood attack, and the engineer should increase the backlog and recycle the 
oldest half-open TCP connections. 


B. There are signs of a malformed packet attack, and the engineer should limit the packet size and set 
a threshold of bytes as a countermeasure. 


C. There are signs of a DNS attack, and the engineer should hide the BIND version and restrict zone 
transfers as a countermeasure. 
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D. There are signs of ARP spoofing, and the engineer should use Static ARP entries and IP address-to- 
MAC address mappings as a countermeasure. 


Answer: A 


Question: 4 


Refer to the exhibit. 


ees 


GET edgron/siiof. php?i-yourght6.cab 
OET = RAR ANIAS AEAN ARORA On: 


2019-12-04 -.. 19461.1178 
2019.12.04 48... 194.61,1.178 
2019-12-04 52... 194.61.1.178 
2019-12-04 -- 19461.1178 
2019-12-04 .. 19461.1178 
2019-12-04 .-. 194611178 
2019-12-04 :08... 194.61.1.178 
2019-12-04 ~.. 194.611.1768 
2019-12-04 .-. 194.61.1.178 
2019-12-04 --- 19481.1178 


EEREEREEERIEN 


‘i 
' Frame 6: 386 bytes on wire (3088 bits), 386 bytes captured (3088 bits) 

> Ethernet Il, Src: HewlettP_1c:47:ae (00:08:02:1c:47:ae), Dst: Netgear_b6:93:f1 

(20:e5:2a:b6:93:f1) 

> Internet Protocol Version 4, Src: 160.192.4.101, Dst: 185.188.182.76 

0000 20 e5 2a b6 93 f1 00 08 02 1c 47 ae 08 00 45 00* ``- GE 
A network engineer is analyzing a Wireshark file to determine the HTTP request that caused the 
initial Ursnif banking Trojan binary to download. Which filter did the engineer apply to sort the 
Wireshark traffic logs? 


A. http.request.un matches 
B. tls. handshake.type ==1 
C. tcp.port eq 25 


D. tcp.window_size == 
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Answer: B 


Reference: 


https://www.malware-traffic-analysis.net/2018/11/08/index 
https://unit42. paloaltonetworks.com/wireshark-tutorial-examining-ursnif-infections/ 


Question: 5 


What is a concern for gathering forensics evidence in public cloud environments? 


A. High Cost: Cloud service providers typically charge high fees for allowing cloud forensics. 
B. Configuration: Implementing security zones and proper network segmentation. 


C. Timeliness: Gathering forensics evidence from cloud service providers typically requires 
substantial time. 


D. Multitenancy: Evidence gathering must avoid exposure of data from other tenants. 


Answer: D 


Reference: https://www.researchgate.net/ 
publication/307871954 About _Cloud_Forensics_ Challenges _and_Solutions 


Question: 6 


Which scripts will search a log file for the IP address of 192.168.100.100 and create an output file 
named parsed_host.log while printing results to the console? 
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A. import os 
import re 
line_regex = re.compile(r”.*fwd=\"192.168.100.100\". *$”) 
output_filename = os_path.normpath( “output/parsed_host.log”) 
with open(output_filename, “w”) as out_file: 
out_file.write(“”) 
with open(output_filename, “a”) as out_file: 
with open( “parsed_host.log”, “r’) as in_file” 
for line in in_file: 
if (line_regex.search(line)): 
print line 
out_file.write(line) 
B. import os 
import re 
line_regex = re.compile(r’.*fwd=\"192.168.100.100\". *$”) 
output_filename = os.path.normpath( “output/parsed_hosts.log”) 
with open(output_filename, “w’) as out_file: 
out_file.write("”) 
with open(output_filename, “a”) as out_file: 
with open( “test_log.log”, “r’) as in_file” 
for line in in_file: 
if (line_regex.search(line)): 
print line 
out_file write(line) 
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C. import os 
import re 
line_regex = re.compile(r’.*fwd=\"192.168.100.10\”. *$") 
output_filename = os.path.normpath( “output/parsed_host.log”) 
with open(output_filename, “w”) as out_file: 
out_file.write("") 
with open(output_filename, “a”) as out_file: 
with open( “parsed_host.log”, “r”) as in_file” 
for line in in_file: 
if (line_regex.search(line)): 
print line 
out_file.write(line) 


D. import os 
import re 
line_regex = re.compile(r’.*fwd=\"192.168.100.100\". *$”) 
output_filename = os.path.normpath( “output/parsed_host.log”) 
with open(output_filename, “w”) as out_file: 
out_file.write("") 
with open(output_filename, “a”) as out_file: 
with open( “test_log.log”, “r’) as in_file” 
for line in in_file: 
if (line_regex.search(line)): 
print line 
out_file write(line) 


A. OptionA 
B. Option B 
C. Option C 


D. Option D 


Answer: A 
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